This notice is prepared under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and its implementing communiqué, to inform data subjects about the personal data processed through the DropLine mobile application and this website.
Identity of the data controller
DropLine is operated by the natural person identified below. Article 3(1)(ı) of the Law defines a data controller as a "natural or legal person", so every obligation described here applies in full.
Data Controllers' Registry (VERBİS)
Under Board decision 2018/32 and subsequent decisions, controllers with fewer than 50 employees and an annual balance sheet below TRY 25 million, whose principal activity is not the processing of special categories of data, are exempt from registering with VERBİS. DropLine falls within this exemption.
The photos and location data processed by DropLine are not among the special categories listed in Article 6, and the application performs no biometric identification, including facial recognition. The registry exemption removes only the registration duty; the duties of disclosure, data security, and erasure continue to apply, and this notice discharges the first of them.
Categories of data, purposes, and legal bases
The table below states the purpose and the Article 5 legal basis separately for each category of data. No data is processed for any purpose not listed here.
| Category | Purpose | Legal basis (KVKK art. 5) |
|---|---|---|
| Identity: display name, optional profile handle | Creating the account, attributing drops to their owner, letting group members recognise one another | Art. 5(2)(c) — necessary for the performance of a contract |
| Contact: e-mail address or phone number | Delivering the one-time sign-in code, sending mandatory account notices | Art. 5(2)(c) — performance of a contract; art. 5(2)(ç) — compliance with a legal obligation |
| Location: latitude and longitude of a drop, optionally the capture location | Placing the photo at the correct point on the map — the core subject of the service | Art. 5(2)(c) — performance of a contract. Since location is the service itself, no separate consent is relied upon. |
| Visual and audio records: photos, videos, captions | Storing content, delivering it to the chosen audience, generating thumbnails | Art. 5(2)(c) — performance of a contract |
| Publicly published content: public profile and DL Point drops | Publishing content on public pages at the user's own election | Art. 5(2)(d) — data manifestly made public by the data subject |
| Transaction security: IP address, device and app version, session tokens, server logs, device key records | Account security, detecting unauthorised access and abuse, debugging, device verification in end-to-end encryption | Art. 5(2)(ç) — legal obligation; art. 5(2)(f) — legitimate interests of the controller |
| Customer transactions: Premium subscription state, purchase record | Granting subscription entitlements, enforcing usage limits | Art. 5(2)(c) — performance of a contract; art. 5(2)(ç) — tax and consumer legislation |
| Moderation: reports, block lists, automated screening results | Detecting illegal and harmful content, resolving reports, protecting users | Art. 5(2)(ç) — legal obligation; art. 5(2)(f) — legitimate interests |
| Device push token | Sending mobile push notifications | Explicit consent — no token is created unless the device notification permission is granted, and it can be withdrawn at any time. |
Method of collection
- Directly from the data subject: contact details entered at sign-up, photos, videos, captions uploaded to the app, and the chosen location.
- Automatically from the device: foreground location where the user has granted permission, the capture place and time embedded in the photo's own metadata, app version, and device type.
- From a third-party identity provider: the identity token (e-mail address and name) supplied when Google sign-in is chosen.
- Automatically on the server side: IP address, timestamps, and error records generated during network requests.
Transfer of personal data
Personal data is transferred to suppliers providing hosting, storage, e-mail delivery, content moderation, notification, and app distribution services, strictly to the extent those services require. The recipients, the purpose, and the data type are set out in a separate table below. Data may also be transferred to legally authorised public authorities and judicial bodies upon a valid request, within the scope of Article 8 of the Law.
Public profile pages and DL Point feeds become visible to anyone on the internet from the moment the user elects to publish them. In the meaning of the Law this is not a transfer but the data subject's own act of making data public.
Transfer abroad
All hosting, storage, e-mail, and moderation infrastructure used by DropLine is located outside Türkiye. Personal data is therefore transferred abroad within the scope of Article 9 of the Law.
As no adequacy decision has been issued by the Board for the recipient countries, transfers are carried out on the basis of the standard contractual clauses published by the Board under Article 9(2)(c), and each executed standard contract is notified to the Board within five business days of signature. The exceptions in Article 9(6), including explicit consent, are reserved for incidental transfers and are therefore not relied upon for permanently operating infrastructure.
For end-to-end encrypted group content, the storage provider abroad holds only encrypted bytes; decryption keys are never transmitted to any server and exist only on the devices within the group.
Retention periods and erasure
- Account and content data: for as long as the account exists. Upon deletion, live data is erased within 30 days at the latest.
- Backups: at most 90 days, as required by the backup cycle; accessible during that period only for disaster recovery.
- Server and security logs: 12 months, the period required to detect unauthorised access retrospectively.
- Reports and moderation records: 2 years from the date of decision.
- Subscription and invoice records: 10 years, under Turkish tax and commercial legislation.
- Expired data is deleted, destroyed, or anonymised under Article 7 of the Law and the associated regulation on erasure, destruction, and anonymisation.
Rights of the data subject (KVKK art. 11)
Under Article 11 of the Law, everyone has the right to apply to the controller and request the following in relation to themselves:
- To learn whether their personal data is being processed.
- To request information if it has been processed.
- To learn the purpose of processing and whether the data is used in line with that purpose.
- To know the third parties, in Türkiye or abroad, to whom the data has been transferred.
- To request rectification of incomplete or inaccurate data.
- To request erasure or destruction under the conditions of Article 7.
- To request that rectification, erasure, or destruction be notified to third parties to whom the data was transferred.
- To object to an adverse outcome produced by analysis solely through automated systems.
- To claim compensation for damage arising from unlawful processing.
Automated decision-making
Images uploaded publicly are passed through an automated screening service for illegal and harmful content. A screening result may temporarily hide an image, but the result is not final and is in every case subject to human review and appeal. End-to-end encrypted group content never enters this screening, as it cannot be decrypted server-side. Beyond this, no solely automated decision-making producing legal or similarly significant effects is applied to data subjects.
How to make an application
Requests concerning the rights above may be submitted through one of the following channels, under Article 5 of the communiqué on applications to data controllers. An application must state the applicant's name, national identity number for Turkish citizens, address or e-mail address for service, telephone number if any, and the subject of the request.
- A wet-signed written petition delivered in person or via notary to the controller's address for service.
- Submission using registered electronic mail (KEP), a qualified electronic signature, or a mobile signature.
- An e-mail sent from the address registered on the account and previously notified to the controller, to the KVKK application address given below.
- Applications are concluded within 30 days at the latest. They are free of charge; where the process incurs a separate cost, the fee set in the Board's tariff may be charged.
- If the application is rejected, the response is found insufficient, or no reply is given in time, the data subject may lodge a complaint with the Personal Data Protection Board within 30 days of learning the response and in any case within 60 days of the application (KVKK art. 14).
Children's data
DropLine is not directed at persons under 13 and does not knowingly collect their data. Users aged 13 to 18 are expected to use the service with the knowledge of a parent or guardian. If data belonging to a person under 13 is found to have been processed, the account and data are deleted without delay; the KVKK application address below may be used to report this.
Data security measures
- Group content is end-to-end encrypted on the device; servers and the storage provider never hold the decryption keys.
- All network traffic is encrypted with TLS; the site is served over secure connections only, enforced by HSTS.
- Photos are re-encoded on the device before upload so that EXIF metadata is stripped; location and device details the user did not choose do not remain in the file.
- Access to private media is granted only through short-lived signed links, which cannot be shared permanently.
- Where unauthorised access is suspected, the breach notification procedure applies: the Board is notified within 72 hours of becoming aware, and affected data subjects as soon as reasonably possible (KVKK art. 12(5)).
Recipients of personal data
| Recipient | Country | Purpose | Data transferred |
|---|---|---|---|
| Railway Corp. | United States | Hosting of the application server and the PostgreSQL database | Account records, drop metadata, location coordinates, server logs |
| Cloudflare, Inc. (R2) | United States | Object storage of photo and video files | Image and video files (end-to-end encrypted for group content), thumbnails |
| Cloudflare, Inc. (DNS/CDN/WAF) | United States | Domain resolution, content delivery, and attack filtering | IP address, request metadata |
| Resend, Inc. | United States | Delivery of the one-time sign-in verification code by e-mail | E-mail address, verification code |
| Google LLC (Cloud Vision SafeSearch) | United States | Automated screening of publicly uploaded images for illegal and harmful content | Thumbnails of public drops only. End-to-end encrypted group content is never sent. |
| Google LLC (Sign-In, Firebase Cloud Messaging) | United States | Google sign-in and mobile push notification delivery | Identity token (e-mail, name), device push token |
| Apple Inc. / Google LLC (uygulama mağazaları) | United States | App distribution and collection of Premium subscriptions | Purchase record and subscription state. Payment card details never reach DropLine. |
| CARTO / OpenStreetMap Foundation | United States / United Kingdom | Serving map tiles to the browser on this website | IP address and the coordinates of the viewed map frame. No drop content is sent. |
Data controller
This notice has not entered into force because the controller's name and address for service are not yet configured. Until they are, the page stays closed to search engines.